Lack of data validation - Path Traversal In python-311
Description
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
debian 11 | - |
1-10 of 14
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1.